Prashanth1812
(Prashanth Pullammagari)
September 28, 2025, 1:07am
1
Hi All,
Need help if you ran into this scenario, TIA
Scenario:
ISC is adding back access to a termed user thru identity refresh even after most of the access are being revoked automatically and adding old entitlements back which were once added through API request.
Note: I have enabled remove all access from UI. Also, we have a before provisioning rule in place to remove all access if LCS = inactive.
Hi @Prashanth1812 , you can read below blog & i am sure, you will get your solution.
Hi everyone,
This workflow auto-revokes any standing access leavers have either through a micro targeted access certifications or by leveraging revoke access requests after being terminated. This should ensure that all leavers’ access is removed upon terminated and not just access assigned through birthright roles. Additionally, an audit trail is generated to document when and why the access was removed.
This workflow was designed and built with the help and input of a multiple people! Thank…
UjjwalJain
(Ujjwal Jain)
September 28, 2025, 9:46am
3
Hi @Prashanth1812 ,
You can make use of workflows to raise an access revoke request and remove all of the user’s access.
iamnithesh
(Nithesh Rao)
September 28, 2025, 1:05pm
4
Inside your BP rule, add this to each of the Remove Entitlement Attribute Requests
attributeRequest.put("assignment", true);
system
(system)
Closed
November 27, 2025, 1:06pm
5
This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.